Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting
ID: f5a9ff3a-034a-5c37-a91c-831eefbd6d35
STIX ID: report--f5a9ff3a-034a-5c37-a91c-831eefbd6d35
Feed Name: The Hacker News
Recorded Future attributes a multi-phase espionage campaign to GRU-linked APT28 (BlueDelta) that used HeadLace malware and credential-harvesting pages across Europe—especially targeting Ukrainian defence entities, rail infrastructure, and related organizations—delivered via spear-phishing and a multi-stage redirection infrastructure (GitHub, InfinityFree, webhook.site, mocky.io) with geofencing and exfiltration via compromised Ubiquiti routers; related Turla activity is also noted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
